Kirsten Whitfield | Fieldfisher
Skip to main content
Professional background

Professional background

Currently I lead multi-national DPO services teams for a variety of clients operating across a wide range of sectors. This includes for clients such as Mitsubishi Tanabe (pharma), Conduent (business process outsourcing, transport technology, call centres and health tech), Figma (digital design and build), Data Axle (data management and marketing) and Viasat (telecommunications and satellite).

I support clients across a broad spectrum of data protection compliance. This includes data protection audits, data and systems mapping, international data transfers (strategic advice and transfer mechanisms including standard contractual clauses, binding corporate rules and transfer impact assessments), data protection impact assessments (including when developing and using AI products), data subject requests and complaints, contracting (data processor clauses, controller data sharing terms, strategy and market positioning), data breach workshops and incident response policies and playbooks.

Building on my background of IT contracting and data protection governance, I help clients find actionable and pragmatic solutions for tackling the ever expanding breadth of EU digital regulation such as the AI Act, Cyber Resilience Act, Critical Entities Resilience Directive, NIS 1, NIS 2 and the Data Act. 

I co-head our Cyber Breach team. Clients highly value my pragmatic and measured approach which is backed by years of experience of handling hundreds of incidents, including large scale multi-national incidents notifiable in jurisdictions around the world. 

Supporting clients through incidents over the years led to recognition that clients needed a robust way to assess and manage incidents and keep a reliable evidence trail. This led to my playing a leading role in developing Fieldfisher's Data Compliance Manager tool which includes GDPR, UK GDPR and NIS 2 incident assessment and management tools.

I regularly work with our Fieldfisher fraud and misconduct investigations experts, helping clients avoid inadvertently breaching data protection law when investigating breaches of the law. 

I was recognised as a stand-out lawyer in Thomson Reuter's 2025 rankings.

Authored pieces

All Resources
A color-coded map of Europe highlights countries in different colors: red for Scandinavia and Iceland, orange for Western Europe, green for parts of Eastern Europe, purple for a central country, and blue for others.
Cyber Security
Insight

NIS2 across the EU

14.11.2025
The EU's NIS2 Directive is a significant development in cyber security, bringing many more sectors into the scope of cyber security regulation and setting out incident notification obligations for in-scope entities, risk management requirements and significant enforcement measures.
Learn more
A low-angle view of modern office buildings with reflective glass and metal facades, rising towards a bright sky. The sun is shining brightly, creating lens flare effects on the buildings. The architectural structures are sleek and contemporary.
Insight

Dawn Raids – Guidelines for Managing an Unannounced External Investigation

28.03.2024
Learn more
A digital illustration of interconnected lines and nodes in a network-like structure. The lines are mainly blue and purple, and the nodes glow with varying intensities, creating a vibrant web against a dark background, evoking themes of connectivity and technology.
Webinar

Webinar: Assessing "high risk AI systems" under the EU AI Act

14.03.2024
Learn more
Insight

Managing personal data breaches – a new approach?

20.12.2023
Learn more
Insight

Is data protection law a barrier to implementing I&D strategies?

24.11.2023
Different sized companies across the banking, real estate, engineering and consulting sectors, contributed to a discussion on the challenges of collecting diversity, equality and inclusion (DEI) data.
Learn more